Wireless Connection Security via Digital Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless connection methods, particularly those using pre-shared keys, are cumbersome and insecure, as they require additional time and effort for setup and do not protect information from unauthorized access, while open connections lack encryption, making users vulnerable to phishing and data exposure.

Innovation Solution

A method and apparatus that utilize a digital certificate to establish a secure wireless connection by verifying the certificate's validity and matching its name with the broadcast name of the wireless access point, eliminating the need for pre-shared keys and ensuring encryption without the complexity of closed connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a closed wireless access point uses pre-shared keys and passwords for encryption, then confidentiality and security are improved, but the connection process becomes cumbersome and requires additional time and effort

Engineering Contradiction:
ImproveconfidentialityVSAvoidconnection process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the security verification process from the traditional pre-shared key model. Instead of requiring users to manually input and manage keys, the system extracts security validation to automated certificate-based authentication, where the access point presents its certificate and the client device automatically verifies it, eliminating manual key distribution while maintaining strong security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces digital certificates as an intermediary between the access point and client devices. Rather than direct key sharing between user and access point, the certificate authority acts as a trusted intermediary that issues certificates to legitimate access points, enabling automated verification without manual key distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If an open wireless access point is used for easy connection, then ease of operation is improved, but information exchanged is not protected and can be viewed by other users

Engineering Contradiction:
Improveconnection processVSAvoidconfidentiality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs security verification in advance during the connection establishment phase. Before any confidential data is transmitted, the client device automatically verifies the access point's digital certificate, ensuring encryption is already in place before the user perceives the connection as established, thus maintaining both ease of use and security

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a wireless access point broadcasts a service set identifier to identify the network, then ease of operation is improved, but unauthorized access points can broadcast similar names to steal user information

Engineering Contradiction:
Improvenetwork identificationVSAvoidphishing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the client device actively verifies the access point's identity through certificate validation. Instead of passively trusting the broadcast SSID, the system sends a verification request to a certificate authority and receives feedback confirming whether the access point is legitimate, thereby preventing phishing attacks while maintaining simple network selection

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10554420B2Wireless connections to a wireless access point
Publication Date: 2020.02.04 KYNDRYL INC
  • US10554420B2 patent drawing
  • US10554420B2 patent drawing
  • US10554420B2 patent drawing

AI summary

A method and apparatus for establishing a wireless connection. A digital certificate having a second name is obtained by a processor unit in response to receiving a selection of a network using a first name broadcast by a wireless access point. A determination is made by the processor unit as to whether the digital certificate is valid. A determination is made by the processor unit as to whether the second name in the digital certificate matches the first name broadcast by the wireless access point. The processor unit establishes the wireless connection to the wireless access point in response to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point.